CVE-2026-63266

Announced: Oct 5, 2026

Fixed in: LibreOffice 26.2.5/26.8.0

Description:

LibreOffice Calc can link a cell range to an external data source, and the link is saved in the document.

Through such a link a document could open an embedded Firebird database that wrote a file to any location the user could write to.

In fixed versions an embedded Firebird database can open or create files only inside its own private directory.

All users are recommended to upgrade to LibreOffice >= 26.2.5 or >= 26.8.0 to avoid this problem.

Credits:

Thanks to Thomas Rinsma and Edoardo Geraci from Codean Labs for reporting this issue.

Thanks to Caolán McNamara of Collabora Productivity for providing the fix.

References:

CVE-2026-63266